So, I opened SR that following two rules are not blocking traffic at all.
operation=add uid=<5fc4795c,00000000,98c0a8c0,00005f8d> target=all timeout=none action=drop log=regular source=cidr:1.2.3.0/24 pkt-rate=0 service=any
operation=add uid=<5fc47a0d,00000000,98c0a8c0,00007701> target=all timeout=none action=drop log=regular source=cidr:4.5.6.0/24 pkt-rate=0 service=any
These are the questions TAC asked me:
1) what are you trying to achieve?
2) which syntax did you use for this rule?
3) What is the business impact ?
4) Are you trying to block IP's or hosts in SecureXL level using dos mitigation?
My answers here:
1. Trying to block network in SecureXL apparently ?
2. Syntax is evident from rule dump
3. Security is compromised, what should be the business impact ?
4. That question I am not going to answer at all.
At the moment I am really hesitating to close this SR and do it some other way.